CVE-2024-21985: Privilege Escalation Vulnerability in ONTAP 9
ONTAP 9 versions prior to 9.9.1P18, 9.10.1P16, 9.11.1P13, 9.12.1P10 and 9.13.1P4 are susceptible to a vulnerability which could allow an authenticated user with multiple remote accounts with differing roles to perform actions via REST API beyond their intended privilege. Possible actions include viewing limited configuration details and metrics or modifying limited settings, some of which could result in a Denial of Service (DoS).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
NetApp ONTAP 9to a version that resolves this vulnerability.Fixed in 9.9.1P18 - Upgrade
Upgrade
NetApp ONTAP 9to a version that resolves this vulnerability.Fixed in 9.10.1P16 - Upgrade
Upgrade
NetApp ONTAP 9to a version that resolves this vulnerability.Fixed in 9.11.1P13 - Upgrade
Upgrade
NetApp ONTAP 9to a version that resolves this vulnerability.Fixed in 9.12.1P10 - Upgrade
Upgrade
NetApp ONTAP 9to a version that resolves this vulnerability.Fixed in 9.13.1P4
Event History
Frequently Asked Questions
What is the severity of CVE-2024-21985?
CVE-2024-21985 is rated as a high severity vulnerability affecting NetApp ONTAP versions prior to certain patched releases.
How do I fix CVE-2024-21985?
To fix CVE-2024-21985, upgrade your NetApp ONTAP system to versions 9.9.1P18, 9.10.1P16, 9.11.1P13, 9.12.1P10, or 9.13.1P4 or later.
Who is affected by CVE-2024-21985?
CVE-2024-21985 affects authenticated users of NetApp ONTAP systems with specific version vulnerabilities when using the REST API.
What actions can be performed due to CVE-2024-21985?
CVE-2024-21985 allows an authenticated user to perform actions beyond their intended privileges via the REST API.
What versions of NetApp ONTAP are affected by CVE-2024-21985?
CVE-2024-21985 affects NetApp ONTAP versions prior to 9.9.1P18, 9.10.1P16, 9.11.1P13, 9.12.1P10, and 9.13.1P4.